Acquisition Started (Endpoint Security)

Prev Next
CEF:0|trellix|hx|9.9.0|Trellix Acquisition Started|Trellix Acquisition Started|0|rt=Feb 05 2019 17:02:11 UTC
dvchost=trellix-01cb28 categoryDeviceGroup=/IDS/Application/Service categoryDeviceType=Forensic Investigation
categoryObject=/Host cs1Label=Host Agent Cert Hash cs1=uP1q4KNadwaber6XLK6BZU dst=10.61.154.186
dmac=00-50-56-01-cb-25 dhost=WIN11b1f2d1fea1 dntdom=WORKGROUP deviceCustomDate1Label=Agent Last Audit
deviceCustomDate1=Feb 05 2019 17:01:52 UTC cs2Label=Trellix Agent Version cs2=29.7.0 cs5Label=Target GMT Offset
cs5=PT0H cs6Label=Target OS cs6=Windows 10 Enterprise 17763 externalId=1 cs3Label=Script Name cs3=Timestamped
Triage deviceCustomDate2Label=Triage Request Timestamp deviceCustomDate2=Feb 05 2019 17:00:22 UTC
categoryOutcome=/Success categorySignificance=/Informational categoryBehavior=/Create act=Acquisition Status
msg=Host WIN11b1f2d1fea1 Timestamped Triage started categoryTupleDescription=A Host Acquisition was successfully
started.

The information listed for the deviceCustomDate2Label and deviceCustomDate2 tags is only provided for triage acquisitions. The information listed for the fname and filePath tags is only provided for file acquisitions.